Criticalscore 60 · flagged Thursday, September 10, 2026

macansumatra.store

Appeared in the .store zone on Thursday, September 10, 2026; by the end of that day the census found active website about gaming. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

page impersonates a brand
matched: PayPal
+22
brand in page title, not in the name
matched: paypal
+20
form on a brand-styled page
matched: has_form
+18
Registrar
Nameserver provider
Nameservers
melina.ns.cloudflare.com, zeus.ns.cloudflare.com
First-day state
active website
HTTP status
200
Page title
SEAGM Indonesia - Situs Belanja Game Online | Top Up Kredit Game & Voucher
Has a form
yes
Brand echoed

Model opinions

Second opinionlooks like phishingtarget: SEAGM (SEA Gamer Mall)confidence 70%· claude-opus-5

The site is a full clone of SEAGM Indonesia's game top-up storefront (title, layout, promos, live chat, PayPal payment branding) served from an unrelated domain (macansumatra.store) behind Cloudflare, with its own 'Masuk'/'Mendaftar' account login and outbound links to the real seagm.com used as decoys — the classic mirrored-storefront setup for harvesting account credentials and payment data.

First passlooks like phishingtarget: PayPalconfidence 85%· claude-haiku-4-5

The page title and content prominently feature 'SEAGM' branding and game-top-up services, but the scorer detected PayPal impersonation with a form present. The page has a login form ('Masuk'/'Mendaftar') and the combination of brand-in-title mismatch (PayPal in title but SEAGM domain/content) suggests credential capture intent, even though the visible content appears to be a game marketplace. The form posts to self with no external verification links, a classic phishing pattern.

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

What the page looked like on Thursday, September 10, 2026

Screenshot of macansumatra.store taken by the zone census on 2026-09-10

Same data as JSON: /api/zone/domain/macansumatra.store. This page is not indexed by search engines and does not link to the site it describes.